GigaWiper: Multi-Stage Destructive Windows Backdoor Combining Disk Wiping, File Encryption, and Boot Sabotage (CyberAv3ngers/Crucio/FlockWiper Lineage)
GigaWiper: Multi-Stage Destructive Windows Backdoor (TL-2026-1167), also tracked as BLUERABBIT, is a high-severity malware campaign, first published 2026-07-10. It is attributed to CyberAv3ngers lineage (Iran) with low confidence, affects Microsoft Windows (all supported client and server versions with a, maps to 33 MITRE ATT&CK techniques (T1007, T1012, T1016), and is covered by 9 detection rules and 28 indicators of compromise.
Key facts for TL-2026-1167
- Threat ID
- TL-2026-1167
- Also known as
- BLUERABBIT
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-07-10
- Last reviewed
- 2026-07-10
- Attribution
- CyberAv3ngers lineage
- Attribution confidence
- LOW
- Nation-state nexus
- Iran
- Motivation
- DESTRUCTION
- Target sectors
- critical infrastructure, water, energy, unspecified broad windows targeting per microsoft
- Target regions
- israel, united states of america, united kingdom, ireland
- Detection rules
- 9
- Indicators of compromise
- 28
Malware and tooling in GigaWiper: Multi-Stage Destructive Windows Backdoor
Malware and tooling: Crucio, CutBrooch, FlockWiper, GigaWiper, MinIO client, RabbitMQ (AMQP), Redis
GigaWiper is a Golang-based Windows backdoor first observed by Microsoft in October 2025 that consolidates a standalone raw-disk wiper, Crucio-derived fake-ransomware encryption (.candy extension, no retained keys), and a reimplemented FlockWiper multi-pass wiper into a single 20-command RabbitMQ/Redis-tasked platform alongside VNC-style remote control, screen surveillance, and event-log wiping. Binary Defense independently tracked the same file set as BLUERABBIT in March 2026 and assesses an Iran-nexus actor (Crucio/CyberAv3ngers lineage) targeting Israeli organizations.
How GigaWiper: Multi-Stage Destructive Windows Backdoor works
GigaWiper is a modular, Golang-compiled Windows backdoor that Microsoft Threat Intelligence disclosed on July 9, 2026, tracing destructive wiping incidents back to October 2025. Unlike single-purpose wipers, GigaWiper is architected as a full command-and-control implant with 20 distinct operator commands spanning destructive, reconnaissance, and surveillance categories, delivered over a RabbitMQ message broker (AMQP, fanout exchange "All" for broadcast and topic exchange "Topic" for targeted routing-key tasking) with results and output returned via Redis as a structured cmd.Result object (error, target_ip, task_id, computer_name, output, pwd, time, status, work_status).
The malware establishes persistence by using PowerShell to register a scheduled task named "OneDrive Update" that runs at both system startup and on a one-minute interval, masquerading as legitimate OneDrive telemetry. A registry value at HKCU\SOFTWARE\OneDrive\Environment tracks execution count to prevent redundant re-initialization.
Destructive capability is delivered through three related-but-distinct code paths that Microsoft assesses were authored by the same developer(s) and stitched together into GigaWiper:
1. Command 1 (WipeMain) performs physical-disk-level destruction: it enumerates physical drives via WMI (Win32_DiskDrive), identifies which drive hosts the Windows installation, strips partition references from the remaining drives via IOCTL_DISK_CREATE_DISK (DeviceIoControl), overwrites raw disk content in 10MB (0xA00000-byte) chunks with a crypto/rand-randomized first byte followed by zero-fill, and forces an immediate, zero-delay reboot. 2. Command 12 (WipeCMain) is a reimplementation of the standalone FlockWiper C tool (first seen on VirusTotal in June 2025, PDB path A:\GRAT\CWipeNew\Release\CWipeNew.pdb) — a multi-pass secure wipe of the Windows installation drive specifically, cycling through 0x00, 0xFF, and random byte patterns with pass-timing telemetry. 3. Command 3 (RanMain / BigBangExtortMain) is fake ransomware whose function name and logic Microsoft matched to the Crucio ransomware family documented in a December 2023 CISA advisory on IRGC-affiliated actors exploiting PLCs (the same lineage publicly tied to CyberAv3ngers water/energy-sector intrusions in the US, UK, and Ireland). It generates a random AES-CBC key/IV that is never persisted anywhere, encrypts files (excluding .exe/.dll), appends a .candy extension, deletes the plaintext originals, and drops a wallpaper image (image_danger.jpg) — producing ransomware-style victim messaging with zero possibility of recovery since no key exists to recover.
Command 2 triggers a BSOD via boot-file deletion; Command 19 wipes System, Setup, Application, Security, and ForwardedEvents Windows Event Logs via `wevutil clear-log`, falling back to direct deletion of C:\Windows\System32\winevt\Logs\Security.evtx if the utility call fails — clearing forensic evidence ahead of or during destructive operations.
Beyond destruction, GigaWiper functions as a full-featured espionage/RAT platform: Command 9 captures per-monitor screenshots; Command 10 records the screen opportunistically when the session is unlocked and the user has been active for more than 10 seconds; Command 20 opens a direct TCP listener providing VNC-like live remote desktop control (screen streaming plus keyboard/mouse injection), protected by a firewall rule deceptively named after the legitimate Windows component "Microsoft.Windows.CloudExperienceHost"; Command 7 executes arbitrary PowerShell with persistent working-directory state; Command 15 collects system information (IP, CPU, OS, and installed antivirus products enumerated via `Get-WmiObject -Namespace root\SecurityCenter2`); Commands 16-18 provide full process, service, and interactive registry management; Command 5 performs bulk AES-256-CBC file encryption/decryption with attacker-supplied keys (a legitimate-use variant of the ransomware primitive); Command 4 exfiltrates files to attacker-controlled storage via a MinIO client; Command 8 manages RabbitMQ Topic-exchange routing-key bindings for individually targeted tasking; and Commands 6/11/13/14 are unused placeholder structures suggesting additional wiper/keylogger modules exist but were not recovered in analyzed samples.
Unstripped GigaWiper PE binaries allowed Microsoft to recover Golang package/function names (rabbit_tools_*, rabbit_bin, cmd_* modules) and identify the recurring debug string "GRAT" across both GigaWiper and FlockWiper artifacts, indicating a shared, still partially unidentified development framework and a probable single threat-actor lineage spanning Crucio (2023), FlockWiper (June 2025), and GigaWiper (October 2025-present).
Microsoft's public blog does not assign country attribution, but independent researcher Binary Defense tracked identical files as "BLUERABBIT" starting March 2026 and assesses an Iran-nexus actor targeting Israeli organizations, consistent with the historical CyberAv3ngers/IRGC-linked Crucio lineage against critical infrastructure. Observed C2 infrastructure: 185.182.193[.]21 (RabbitMQ on TCP/5544, Redis on TCP/7542) with 212.8.248[.]104 as apparent backup/secondary C2.
Microsoft Defender AV/EDR detects the family under Giga, Wiper, FlockWiper, and CutBrooch naming, with behavioral detections WprFlock and WprCree, and has published a Threat Analytics "Tool profile: GigaWiper" report. Recommended mitigations focus on tamper protection (blocking AV/EDR disablement and exclusion changes), disabling GPO-based local-admin AV exclusion merges, cloud-delivered protection, EDR in block mode, and attack-surface-reduction rules blocking unsigned/low-prevalence executables — alongside treating any confirmed GigaWiper intrusion as a business-continuity emergency requiring immediate isolation, backup verification, and C2 blocking before destructive commands can propagate.
MITRE ATT&CK techniques used in TL-2026-1167
Discovery
T1007 System Service Discovery; T1012 Query Registry; T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1120 Peripheral Device Discovery; T1518 Software Discovery
Lateral Movement
Defense Evasion
T1036 Masquerading; T1070 Indicator Removal
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Persistence
T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution
Privilege Escalation
Credential Access
Execution
T1059 Command and Scripting Interpreter; T1106 Native API; T1569 System Services
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1219 Remote Access Tools
Collection
T1074 Data Staged; T1113 Screen Capture
defense-impairment
T1112 Modify Registry; T1685 Disable or Modify Tools
Impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1489 Service Stop; T1491 Defacement; T1499 Endpoint Denial of Service; T1529 System Shutdown/Reboot; T1561 Disk Wipe
Affected products and versions in GigaWiper: Multi-Stage Destructive Windows Backdoor
- Microsoft — Windows (all supported client and server versions with a physical or virtual disk)
Vulnerable versions: Windows 10; Windows 11; Windows Server
Remediation for GigaWiper: Multi-Stage Destructive Windows Backdoor
Immediate actions
- Block C2 IPs 185.182.193[.]21 and 212.8.248[.]104 (RabbitMQ TCP/5544, Redis TCP/7542) at perimeter and DNS/egress firewalls
- Isolate any host running a scheduled task named 'OneDrive Update' or with HKCU\SOFTWARE\OneDrive\Environment registry value present
- Preserve forensic evidence and verify offline/immutable backups before further triage — treat as a business-continuity emergency
- Hunt for wevutil clear-log invocations against System/Setup/Application/Security/ForwardedEvents logs and for direct deletion of Security.evtx
- Restrict local administrator rights to prevent tamper-protection bypass and antivirus exclusion changes
Workarounds
- Block outbound AMQP (5672 and non-standard RabbitMQ ports) and Redis (6379 and non-standard ports) to unrecognized external hosts
- Alert on scheduled tasks created via PowerShell with minute-interval triggers disguised as update tasks
Longer-term hardening
- Deploy EDR with behavioral detection tuned for WprFlock/WprCree/FlockWiper/GigaWiper signatures
- Enable Microsoft Defender Tamper Protection and disable GPO-based local-admin AV-exclusion merge (DisableLocalAdminMerge)
- Enable Attack Surface Reduction rules blocking execution of unsigned/low-prevalence/low-age executables
- Enable Automated Investigation and Remediation and EDR in block mode
- Implement offline/immutable, air-gapped backup strategy resilient to full-disk wipe scenarios
- Monitor for firewall rules masquerading as legitimate Windows components (e.g., 'Microsoft.Windows.CloudExperienceHost')
Weaknesses (CWE) in GigaWiper: Multi-Stage Destructive Windows Backdoor
CWE-506, CWE-311, CWE-778
Timeline of GigaWiper: Multi-Stage Destructive Windows Backdoor
- CISA publishes joint advisory AA23-335A on IRGC-affiliated cyber actors (CyberAv3ngers) exploiting internet-exposed PLCs at water/wastewater facilities; documents the Crucio ransomware family whose BigBangExtortMain encryption logic later appears verbatim in GigaWiper Command 3
- FlockWiper, a standalone C-based multi-pass Windows-drive wiper carrying the 'GRAT' PDB debug string (A:\GRAT\CWipeNew\Release\CWipeNew.pdb), is first uploaded to VirusTotal — its wiping logic is later reimplemented as GigaWiper Command 12 (WipeCMain)
- Microsoft Threat Intelligence first observes Windows environments being wiped, marking the earliest documented destructive GigaWiper activity
- Binary Defense independently identifies the same file set under the name BLUERABBIT, assessing an Iran-nexus actor targeting Israeli organizations
- The Hacker News, SC Media, Cyberpress, Security Affairs, and Hackread publish independent coverage summarizing Microsoft's findings and amplifying IOCs
- Microsoft Defender Threat Analytics concurrently publishes a 'Tool profile: GigaWiper' report, adding Defender detection naming (Giga, Wiper, FlockWiper, CutBrooch) and behavioral detections (WprFlock, WprCree) for defender consumption
- Microsoft publishes 'GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware,' detailing the 20-command RabbitMQ/Redis backdoor architecture, unstripped-binary Golang package/function-name recovery, IOCs, and detection guidance
- Cyber Security News publishes a technical summary article covering GigaWiper's disk-wiping, encryption, and boot-sabotage capabilities, prompting hunt intake into this pipeline
Sources cited for GigaWiper: Multi-Stage Destructive Windows Backdoor
- GigaWiper Malware Attacking Windows Systems
- GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
- New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
- GigaWiper Merges Three Malware Families Into One Destructive Backdoor
- Microsoft Warns of GigaWiper Backdoor Built to Destroy Windows PCs
- Microsoft details GigaWiper destructive backdoor assembled from older tools
- Microsoft Warns GigaWiper Merges Crucio and FlockWiper Code Into Destructive Backdoor
Threats related to GigaWiper: Multi-Stage Destructive Windows Backdoor
- GigaWiper (aka BLUERABBIT): Golang-Based Destructive Backdoor Combining Wiper, Fake Ransomware, and C2 Capabilities
- GigaWiper (BLUERABBIT) — Go-Based Modular Backdoor Bundles Raw Disk Wiper, Crucio-Derived Fake Ransomware, and FlockWiper Drive Overwriter Behind Espionage Tooling
- GigaWiper (BLUERABBIT): Golang Backdoor Bundling Physical-Disk Wiping, Crucio-Derived Fake Ransomware, and FlockWiper-Derived Multi-Pass Wiping
- Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguards
- Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with AI-Assisted Reconnaissance Post Iran-US Escalation (Feb 28, 2026)
Detection coverage for TL-2026-1167
As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1167 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1167
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.